Security

What should be on a data room security checklist before you upload anything

The specific settings and certifications to confirm, not general reassurance about encryption.

Vault Index desk / 18 August 2026 / 8 min read

The short answer

A data room security checklist covers eight specific items: two factor authentication for every user, granular per document and per user permissions, dynamic watermarking, download and print controls, screen capture protection, a full audit log of every view and download, clear data residency and hosting location, and a documented backup and disaster recovery policy. Confirming these eight, with evidence rather than a marketing claim, covers the practical risk in almost every transaction.

None of this replaces basic organisational discipline, restricting who internally has admin rights, and revoking access the day a deal ends rather than weeks later, which causes more real world leaks than any technical weakness in the platform itself.

1) Authentication and access control

Confirm two factor authentication is available and can be made mandatory for every external viewer, not optional. Confirm permissions can be set per document and per viewer, view only, print allowed, download allowed, rather than only at the folder level, since folder level control alone forces an administrator to either over expose or under expose material.

Ask specifically how access is revoked: whether revocation is instant and applies even to documents already downloaded through the platform's own viewer, since some watermarked PDF downloads remain readable offline after revocation while others expire.

2) Document protection in use

Confirm dynamic watermarking stamps the viewer's name, email and a timestamp on every page at the point of viewing, not just on download, since this is what deters and traces leaks. Confirm whether the platform offers screen capture protection or at least detection, recognising that no software can fully prevent someone photographing a screen, but that some platforms make casual copying meaningfully harder than others.

Check print and download controls can be set independently, since a viewer who should be able to read but not retain a document needs view only with printing disabled, not just a download block that still permits printing to PDF.

3) Certification, hosting and audit trail

Ask the vendor directly for their current ISO 27001 certificate and SOC 2 report rather than relying on a badge shown on the marketing site, since certifications lapse and scope varies. Confirm where customer data is physically hosted and whether that satisfies UK GDPR or EU GDPR requirements for the parties involved, particularly where the deal involves personal data on employees or customers.

Confirm the audit log records every view, download and print action with a timestamp and viewer identity, and that this log can be exported, since it is the evidence a seller relies on if a leak is ever disputed after the deal closes.

4) Backup, continuity and offboarding

Ask what backup and disaster recovery policy applies to the room's contents, and what the vendor's stated uptime commitment is, since a room that goes offline during a live negotiation has real commercial consequences. Confirm what happens to data after the deal closes, whether documents are retained, for how long, and under what process they are permanently deleted, since indefinite retention of a failed deal's sensitive documents is itself a liability.

Finally, build an internal offboarding step into the deal process itself: the day a deal completes or falls through, revoke every external viewer's access from the platform administration panel rather than trusting that access will simply lapse or that a departed advisor will remember to ask for removal.

Closing note

For how individual platforms score against these criteria, see the full ranking at /rankings and the method at /methodology. Current pricing across the vendors compared here is at /pricing.

Sources and further reading

Vendor figures rechecked 1 September 2026